Training & Certification

A repeatable program turns a founder-built method into an institution: every assessment, every record, every attestation runs the same way regardless of who holds the pen.

Confidential · June 2026. This document describes the intended training and certification scheme for the govrn delivery organization. Today the standard is exercised by the founding team on synthetic data; the certification levels and counts below are the structure we are building toward, not a credential register that exists yet. Independence between the building/operating body and the attesting body is an intended structure (pre-entity today).

Why a certification scheme

The govrn standard is only worth its name if a record produced in one engagement means the same thing as a record produced in another. Repeatability is the product. The curriculum below trains people to run the arc — Assess → Design → Implement → Operate → Attest → re-baseline — identically, and the certification levels gate who is allowed to do what, with the sharpest line drawn around attestation.

The program maps directly onto the roles in team: the curriculum is the on-ramp from a new hire into a Lead Assessor, Solutions Architect, Governance Engineer, Delivery Lead, or Attestation Lead.

Curriculum modules

Every track draws from a shared module library; tracks differ in depth and which modules are mandatory.

ModuleCovers
M1 — The Standardgovrn = See + Prove; the assessment plus attestation logic; what "never self-certified" means
M2 — The Three LensesTechnology, Security, AI lens scopes, evidence requirements, and boundaries
M3 — Product-AI Reviewreviewing the AI a company ships; fair-housing / tenant-screening exposure (the Grace Hill "Gracie" pattern)
M4 — The CrosswalksNIST AI RMF, ISO/IEC 42001, EU AI Act, OWASP, MITRE ATLAS, CSF 2.0 mappings
M5 — The ToolchainOPA/Rego, OSCAL, Langfuse, OpenTelemetry, Atlas/Marquez, SIEM/IdP/secrets
M6 — The Aperture Enginemetadata-only ("pointers, not payloads"), deterministic measurement, shadow-AI surfacing, cost attribution
M7 — Independence & Ethicsseparation of duties; conflict firewalls; "modeled" vs "measured" honesty discipline
M8 — The Delivery Methodthe engagement arc, the annuity loop, re-baselining, evidence handling, client handoff

Certification tracks

Each track is a mandatory module subset plus a practicum on synthetic or sanctioned client data.

Certification levels

Levels stack: each requires the one below it.

What each level unlocks

LevelPrerequisiteCan do / signExamRecert
AssociateContribute, operate engine supervised; signs nothingOpen-book written24 mo
PractitionerAssociate + trackLead track execution; author record sectionsTrack exam + practicum24 mo
Lead / AssessorPractitioner + 1 reviewed engagementOwn record; sign assessment & designPortfolio review18 mo
AttestorLead + M7 masterySign independent attestationProctored independence practicum12 mo

Independence is a hard requirement, not a perk

The Attestor credential exists to enforce structural separation of duties: an attestation is valid only when the signer is independent of the body that built and ran the record. The shorter 12-month recert reflects that an attestation is valid only against a fresh record — the annuity loop's continuous measurement applies to the attestor's currency too. No one signs an attestation on an estate they assessed, designed, implemented, or operated. The curriculum trains the discipline; the certification gates it; the eventual entity structure makes it enforceable.